We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

FortiBleed: 86,000 Fortinet firewalls compromised (SMB VPNs)

Credentials for 86,000 Fortinet firewalls and VPNs have been circulating since mid-June 2026 (CISA alert). If you use a FortiGate, here's how to check and take action.

FortiBleed: 86,000 Fortinet firewalls compromised (SMB VPNs)

In summary: Stolen credentials from more than 86,000 Fortinet devices—many of which are used by companies for VPN access—have been compiled and distributed. For an SME using a FortiGate, the key step is not to panic but to quickly verify VPN accounts and change passwords.

What Happened

In mid-June 2026, researchers at Hudson Rock disclosed a database dubbed “FortiBleed”: a collection of login credentials associated with Fortinet firewalls and VPN gateways. Estimates vary by source, with between 74,000 and 86,644 devices affected in nearly 194 countries.

The U.S. agency CISA issued an alert on June 18 and then updated it on June 22 to refer users to Fortinet’s official recommendations. Not all of these credentials were obtained on the day of the leak: some came from devices compromised earlier in the year, sometimes through vulnerabilities that Fortinet had already patched but that remained unpatched in the field. The time lag between when a patch becomes available and when it is applied remains the weak point.

Does this apply to me?

You may be at risk if your company uses a FortiGate firewall with SSL VPN access for remote work or remote sites, especially if the administration interface or VPN portal remains accessible from the internet. The specific risk: a valid set of credentials allows an attacker to log in as a legitimate user without triggering any obvious alerts.

Here are a few things to look out for: VPN connections at unusual times, from countries where you don’t have employees, or accounts whose passwords haven’t been changed in a long time. If you’ve outsourced your network management to a service provider, ask them for written confirmation that your devices have been checked.

What to Do Now

Three actions, in order of priority:

  1. Reset the VPN and administrator passwords on your Fortinet devices, and terminate any active sessions. This is the step that neutralizes a credential that has already been compromised.
  2. Enable phishing-resistant two-factor authentication for VPN and admin access. A stolen password alone will no longer be enough to gain access.
  3. Review the login logs from the past few weeks to identify any unusual access, and apply the latest Fortinet patches if you haven't already done so.

If you don't have the in-house expertise to handle this equipment, this is exactly the kind of check that a managed services contract or a security provider should perform. A quick check is better than a delayed audit. Let's discuss this if you have any questions.

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

In a nutshell

FortiBleed isn't a spectacular new vulnerability, but a reminder that a stolen VPN credential opens a backdoor. Changing Fortinet passwords, enabling two-factor authentication, and reviewing logs are enough to mitigate most of the risk. With the right support, an SMB can resolve this in a matter of hours, without making a big deal out of it.

— Samir Amara, CEO — IT Systèmes

Frequently asked questions

Should we replace our Fortinet firewall? No. The hardware isn't the issue here; it's the exposed credentials. Resetting access credentials and applying patches is sufficient in the vast majority of cases.

We use a different VPN—are we safe? For this specific incident, yes. But the best practice remains the same: two-factor authentication and up-to-date passwords for all remote access.

Our latest articles

See more
Processing Electronic Invoices Using an AI Accounting Agent
Development & automation

AI Accounting Agent: What It Does with Electronic Invoices

Receiving electronic invoices will be mandatory starting in September 2026: what an AI accounting agent adds to your software, starting at what volume, and at what price.
September 23, 2026
AI illustration agent
Development & automation

AI Agents for HR: Use Cases, Legal Framework, and Deployment Methods

Onboarding, recruitment, HR questions: what an AI agent can handle, what the AI Act, the GDPR, and the Labor Code require, and how to measure it.
September 23, 2026
AI Help Desk Illustration
MSP & Managed IT Services: Proactive IT Management for Small and Medium-Sized Businesses

AI Help Desk for SMEs: 2026 Comparison of Solutions

Managed service with an AI agent or AI-powered help desk software: two categories, two pricing models. Comparison of Helpy (IT Systèmes), Witivio, Freshservice, Zendesk, and Moveworks; prices as of September 2026.
September 17, 2026
Hyperdevelopment: AI-Accelerated Software Development at IT Systèmes
Development & automation
Data & AI

Hyperdevelopment: What Is AI-Accelerated Software Development?

Hyperdevelopment, an IT Systèmes method that reduces code production time by a factor of 10: audit, validated prototype, supervised AI generation.
September 17, 2026

Logitech Options+ Vulnerability (CVE-2026-12518): Should Small and Medium-Sized Businesses Apply the Patch Immediately?

A high-severity vulnerability (CVSS 8.5, CVE-2026-12518) affects Logi Options+, the software that controls Logitech mice and keyboards on a large portion of the corporate Windows fleet. It allows a standard user to gain full system privileges on their workstation. The patch has been available since late August; the question now is how urgently it should be deployed.
September 18, 2026
illustration: managed social media
MSP & Managed IT Services: Proactive IT Management for Small and Medium-Sized Businesses
Cybersecurity

MDR: Definition, Scope, and Differences from a Managed SOC

MDR is a managed detection and response service built on an XDR solution. Definition, actual scope, blind spots, and how it differs from a managed SOC.
September 17, 2026